The KEV bar

The vast majority of disclosed vulnerabilities are never exploited in the wild. The KEV catalog is the short, high-signal list of CVEs with confirmed exploitation evidence — the ones that change a remediation priority.

Patching what matters

Because KEV entries carry binding remediation deadlines, they convert vulnerability data into an operational directive: patch these, in this order, now. That is why H3XA surfaces KEV context directly on vulnerability objects.

What this means

When a vulnerability appears in H3XA with KEV context, treat it differently from the surrounding corpus. It is not merely disclosed — it is being used.